← Back to malem Updated 19 July 2026

Privacy policy

This page explains what the Malem web service stores, what remains on your device, and when information is sent to travel-planning or image providers.

Short version

Your account, profile, trips, group, and journal are stored by Malem so they are available anywhere you sign in. The browser also keeps a local cache. Passwords are never stored as readable text. Journal entries are private unless you explicitly mark an entry public. Malem does not use advertising trackers or sell personal information.

What Malem stores for your account

The same customer content is cached in this browser for fast rendering and degraded operation. Clearing browser data removes that local cache but does not delete the account. Use Settings → Delete account to permanently remove the account, sessions, and synchronized content.

What remains on this device

Theme and interface preferences, optional model/provider settings, optional provider API keys, model cost traces, image-search keywords, and outfit-ranking actions remain in this browser and are not synchronized to your Malem account. Clearing this site's browser data removes them.

What Malem does not do

Optional integrations you can enable

OpenRouter and model providers

When live itinerary research is enabled, Malem sends the trip request and relevant profile constraints to the server-side OpenRouter workflow. OpenRouter routes the request to the models selected in Settings. The server owns the OpenRouter key; it is never exposed to the browser. Review OpenRouter's privacy information and the selected model provider's policy.

Optional direct OpenAI or Anthropic connection

If you enter your own OpenAI or Anthropic key, that key stays in this browser and requests are sent to that provider under its terms. Browser-stored keys can be read by JavaScript running on this origin, so use a limited, revocable key and remove it when no longer needed.

Pinterest inspiration

The Outfit inspiration page sends bounded public-image searches built from destination, season, itinerary setting, wardrobe presentation, modesty preference, and optional style keywords through Malem's same-origin search route. It requests full-outfit inspiration, not private Pinterest content. Images are normally loaded from their source host and may use Malem's allowlisted image proxy if direct loading fails. Source-host privacy policies still apply.

Community journal

Entries marked “Publish publicly” are returned by the public community endpoint with the entry text, author display name, destination, and selected accuracy notes. Private entries are never returned there. Turning publication off and saving the journal state removes the entry from future community responses.

Security

Passwords are processed with PBKDF2-SHA256 and a unique random salt. Malem stores only the derived password hash. Sessions use random HttpOnly, SameSite cookies; only a SHA-256 hash of the session token is stored by the service. Production cookies are Secure and sessions expire after 30 days.

No internet service can promise perfect security. Use a unique password, keep sensitive health notes to the minimum needed for planning, and delete information you no longer want stored.

Children

Malem is not directed at children under 13. Trip planning features include fields for children's ages and family constraints so an adult traveler can plan for their family, but children should not create accounts.

Changes

If this policy changes, the updated date at the top of this page will change and the new version will be visible at this URL.

Contact

Malem is maintained at github.com/kikhiamasahcollege-ai/malem. Questions and issues can be filed there.